Skip to main content
SparkSolutions

AI Risk & Security · SparkSolutions Editorial

Your Cyber Insurance May Not Cover an AI-Caused Loss Anymore

Insurers are quietly rewriting liability and cyber policies to exclude losses caused by a policyholder's own AI tools, not just attacks that use AI. For a business running a chatbot, agent, or automation, that gap is worth finding at renewal, not during a claim.

By SparkSolutions Editorial · Published August 14, 2026 · 5 min read

Share

For most of the last decade, a commercial cyber policy was written around a fairly stable idea: someone attacks you — ransomware, a breach, a phishing-driven wire transfer — and the policy responds. That assumption has started to come apart this year, not because insurers stopped covering attacks, but because a growing share of the losses businesses are now reporting don't fit that shape at all. They come from a company's own AI tool doing something it shouldn't: a customer-facing agent giving advice that leads to a real financial loss, an internal automation approving a transaction it should have flagged, a chatbot output that turns out to be defamatory or lifts someone else's copyrighted material. Insurers have noticed, and 2026 has been the year several of them started writing that kind of risk out of standard policies rather than pricing it in.

The clearest sign is on the general liability side. Insurance Services Office, the industry body that drafts the standard policy language most commercial insurers build from, introduced new exclusion endorsements this year aimed specifically at generative AI output — barring coverage under the bodily-injury, property-damage, and advertising-injury sections of a standard policy for harm traceable to what a generative AI system produced or did on the policyholder's behalf. A business that has spent years assuming its general liability policy has its back if a piece of software says something wrong should not assume that anymore. The exclusion has nothing to do with whether a hacker got in. It turns on whether the AI system the business itself deployed is what caused the harm.

The cyber policy side is fragmenting in a related but distinct way. Those policies were built around specific trigger events — unauthorized access, a data breach, funds-transfer fraud — and most still respond reasonably well when an attacker uses AI as a tool to pull off a familiar kind of attack, a more convincing phishing email or a cloned voice, because the underlying event is still unauthorized access or fraud in the classic sense. The harder case is a loss where nobody broke in at all: the business's own AI agent, acting within the access it was legitimately given, does something costly. That does not cleanly trigger a breach-based cyber policy, it may not clear the new AI carve-outs in general liability, and it was never really what a directors-and-officers or employment-practices policy was underwriting either. The loss can end up in a gap between several lines of coverage, each with a reasonable argument that it belongs to one of the others.

This matters most for the businesses that have moved fastest on the last two years of AI deployment — the ones running a customer-facing chatbot, a voice agent, or an automation that takes real actions inside company systems, often built quickly and sensibly by a small internal team, without anyone separately circling back to the insurance broker to ask whether the existing coverage still holds. It is an easy thing to overlook, because deploying the tool rarely feels like a change to the business's risk profile the way opening a new location or bringing on outside contractors obviously does. The gap tends to surface for the first time during a claim, which is the most expensive possible moment to discover it.

A few insurers have started responding constructively rather than simply narrowing what they'll cover. Specialized AI-risk riders are appearing that extend coverage specifically to AI-caused losses, but they ask for something in return: documented evidence that the system was tested before deployment, that someone reviews its output on an ongoing basis, and that a human sits in the loop for consequential decisions. That detail is worth noting on its own, apart from the insurance question, because it means the operational habits a careful business should already have around any customer-facing AI tool — a defined scope, a named owner, a review process, an escalation path for anything ambiguous — are becoming the specific evidence an underwriter wants to see before writing a policy. Governance is turning from a risk-management nicety into a condition of coverage.

The practical step is a conversation, not a purchase. At the next renewal, or sooner if renewal isn't imminent, ask the broker directly and get the answer in writing: does this policy cover a loss caused by an AI tool the business itself deployed and controls, as distinct from a loss caused by someone else's attack. Bring the specific tools in use — a named agent, a chatbot vendor, an internal automation — rather than asking about AI risk in the abstract, because a vague answer to a vague question is not something to rely on when a claim is actually filed. If the honest answer is that current coverage doesn't reach that scenario, that's worth knowing now, as a policy question, rather than later, as a dispute over whether the policy responds at all.

None of this is a reason to slow down deploying AI tools that are genuinely improving how a business runs. It is a reason to treat the insurance side of that deployment with the same seriousness as the technical and legal sides. The businesses that get caught by this coverage gap will not be the ones that used AI carelessly. They will be the ones that used it well, assumed the coverage they already had would follow along, and never asked.

  • cyber insurance
  • ai risk
  • risk management
  • business insurance
  • ai governance

Keep reading

Let's discuss what's slowing your business down.

Every engagement starts with understanding your operational pain points. Talk to our team about where intelligent software and automation can deliver measurable results.